Skip to main content
Threatstealth
Login
// PRIVACY.FRAMEWORKS

30 privacy laws and frameworks, one reference

From GDPR and CCPA/CPRA to LGPD, PIPL, APPI, and ISO 27701 — the global data-protection landscape with jurisdiction, year, and enforcement type.

Reviewed by Threatstealth Security Architects·Aligned to SOC 2 · ISO 27001 · NIST CSF · PCI DSS V 4.0.1
// DEFINITION

What is Privacy compliance automation?

Privacy frameworks and laws govern the collection, processing, storage, and transfer of personal data. They establish individual rights, organisational obligations, and enforcement mechanisms. The global landscape has expanded rapidly since 2018: more than 130 countries now have data-protection legislation, and most enterprises must comply with three or more privacy regimes simultaneously. This reference catalogues 30 of the most consequential privacy frameworks worldwide.

// THE.PROBLEM

The fragmented privacy compliance burden

  • GDPR-style laws exist in over 130 countries — each with subtly different definitions of personal data, lawful basis, and transfer rules
  • Sector-specific laws (HIPAA, FERPA, GLBA, COPPA) layer additional requirements on top of general privacy regimes
  • Cross-border transfers require legal mechanisms (SCCs, BCRs, adequacy decisions) that change as adequacy decisions are challenged
  • Subject-rights workflows (access, erasure, portability, opt-out) must be implemented across every data store the organisation operates
// HOW.IT.WORKS

A four-step operational model

1

Map your data flows

Identify every system that processes personal data, the categories collected, the legal basis for processing, and the jurisdictions involved.

2

Apply the controlling law per data subject

Most laws apply based on the data subject's residency or location at the time of processing, not the company's headquarters.

3

Implement subject-rights workflows

Standardise access, rectification, erasure, portability, and opt-out workflows so a single request can be honoured across all in-scope systems.

4

Document and review continuously

DPIAs, ROPAs, and breach notification procedures are continuous obligations — not one-time deliverables.

30
Privacy frameworks tracked
130+
Countries with data-protection laws
€20M
Maximum GDPR fine
72h
GDPR breach notification window
// REFERENCE.01

Complete Privacy Frameworks Reference (30)

Every major privacy law and framework worldwide — full name, jurisdiction, year of effect, and whether the regime is mandatory or voluntary.

Framework / LawFull NameJurisdictionYearType
GDPRGeneral Data Protection RegulationEU2018Mandatory
CCPA/CPRACalifornia Consumer Privacy Act / Rights ActUSA (California)2020/2023Mandatory
HIPAA Privacy RuleHealth Insurance Portability and Accountability ActUSA1996Mandatory
PIPEDAPersonal Information Protection and Electronic Documents ActCanada2000Mandatory
LGPDLei Geral de Proteção de DadosBrazil2020Mandatory
PDPAPersonal Data Protection ActThailand / Singapore2022 / 2012Mandatory
POPIAProtection of Personal Information ActSouth Africa2021Mandatory
APPIAct on the Protection of Personal InformationJapan2005Mandatory
PIPLPersonal Information Protection LawChina2021Mandatory
PDPBPersonal Data Protection BillIndiaPendingProposed
Privacy ActPrivacy Act of 1974 / Privacy Act 1988USA / Australia1974 / 1988Mandatory
ePrivacy DirectiveEU Cookie and Electronic Communications DirectiveEU2002Mandatory
NIST Privacy FrameworkPrivacy Framework v1.0USA2020Voluntary
ISO/IEC 29100Privacy Framework StandardInternational2011Voluntary
ISO/IEC 29101Privacy Architecture FrameworkInternational2013Voluntary
ISO/IEC 27701Privacy Information Management SystemInternational2019Voluntary/Certifiable
OECD Privacy GuidelinesGuidelines on the Protection of Privacy and Transborder Data FlowsInternational1980 / 2013Voluntary
APEC Privacy FrameworkAsia-Pacific Economic Cooperation Privacy FrameworkAsia-Pacific2004 / 2015Voluntary
FTC Act Section 5Federal Trade Commission Unfair/Deceptive PracticesUSA1914Mandatory
FERPAFamily Educational Rights and Privacy ActUSA1974Mandatory
COPPAChildren's Online Privacy Protection ActUSA1998Mandatory
GLBAGramm-Leach-Bliley ActUSA1999Mandatory
SHIELD ActStop Hacks and Improve Electronic Data Security ActUSA (NY)2020Mandatory
KVKKPersonal Data Protection LawTurkey2016Mandatory
PDPL (KSA)Personal Data Protection LawSaudi Arabia2021Mandatory
BCRBinding Corporate Rules (GDPR mechanism)EUOngoingVoluntary
SCCsStandard Contractual ClausesEU2021Voluntary
Privacy Shield (defunct)EU-US Privacy Shield FrameworkEU / USA2016–2020Defunct
DIFC DP LawDubai International Financial Centre Data Protection LawUAE2020Mandatory
ADGM DP RegulationsAbu Dhabi Global Market Data Protection RegulationsUAE2021Mandatory
30 entries
// WHY.IT.MATTERS

Outcomes for security teams

Fines now reach the hundreds of millions

GDPR maximum penalties are €20M or 4% of global turnover. CCPA/CPRA, LGPD, and PIPL all carry comparable enforcement powers.

Privacy is a board-level risk

Customer trust, market access, and partnership eligibility all depend on demonstrable privacy compliance.

Subject rights are the new operational floor

Honouring access and erasure requests at scale requires data inventories that most organisations only build under regulatory pressure.

// FAQ

Direct answers

Does my US-based company need to comply with GDPR?+

Yes, if you process personal data of individuals located in the EU — GDPR applies extraterritorially regardless of where the controller or processor is established.

How is CPRA different from CCPA?+

CPRA (effective 2023) extends CCPA with new rights (correction, opt-out of sharing for cross-context behavioural advertising), creates a sensitive-personal-information category, and establishes the California Privacy Protection Agency as the dedicated enforcement body.

Is ISO 27701 a substitute for GDPR compliance?+

No. ISO 27701 certification demonstrates a robust Privacy Information Management System, which materially supports GDPR compliance, but does not replace the legal obligations of the regulation itself.

What is the status of EU–US data transfers after Privacy Shield?+

Privacy Shield was invalidated in 2020 (Schrems II). Transfers now rely on Standard Contractual Clauses, Binding Corporate Rules, or — since 2023 — the EU–US Data Privacy Framework adequacy decision, which itself faces ongoing legal challenge.

Closed · Expert Access

Ready to see it in your environment?

Request a private security demo from the Threatstealth team.